Unrated severityNVD Advisory· Published Dec 14, 2024· Updated Apr 8, 2026
WP Job Portal <= 2.2.2 - Missing Authorization to Unauthenticated Arbitrary Resume Download
CVE-2024-11712
Description
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and including, 2.2.2. This makes it possible for unauthenticated attackers to download other users resumes.
Affected products
2- Range: <=2.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- gist.github.com/g1-nhantv/245d2829c1b489f61c9124086506b6b8mitre
- gist.github.com/g1-nhantv/7a26a9681eb3413d8be9323fb151fdcdmitre
- plugins.trac.wordpress.org/changeset/3202327/wp-job-portal/tags/2.2.3/modules/resume/model.phpmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/ecc87d5f-dba4-40f8-946f-f2634614b579mitre
News mentions
0No linked articles in our index yet.